
===== HOST =====

Hostname:   ana-docker.phasefinal.com
Date:       2026-04-20T14:27:52-07:00
Uptime:     up 2 weeks, 6 days, 15 hours, 36 minutes
OS:         Debian GNU/Linux 12 (bookworm)
Kernel:     6.1.0-44-amd64
Arch:       x86_64

===== HARDWARE =====

CPU cores:  8
CPU model:  QEMU Virtual CPU version 2.5+
MemTotal:   15.6 GB
MemAvailable: 11.1 GB

===== GPUS =====

nvidia-smi not present (no NVIDIA GPUs or driver not installed)

===== FILESYSTEMS (df) =====

Filesystem                       Size  Used Avail Use% Mounted on
/dev/sda1                        245G   79G  153G  34% /
10.250.50.50:/mnt/docker          20T     0   20T   0% /mnt/compose
10.250.50.50:/mnt/backup          20T  1.1G   20T   1% /mnt/backup
10.250.50.50:/mnt/pve-VMStorage   22T  2.4T   20T  11% /mnt/tnvms

===== PERSISTENT MOUNTS (/etc/fstab, non-comment) =====

UUID=1f0fecb0-efcf-4403-a180-f67cb4615f48 /               ext4    errors=remount-ro 0       1
UUID=ab0fa49a-61d4-4b2a-af7e-bc32f84bbd3b none            swap    sw              0       0
/dev/sr0        /media/cdrom0   udf,iso9660 user,noauto     0       0
10.250.50.50:/mnt/docker /mnt/tndocker nfs noauto,x-systemd.automount 0 0
10.250.50.50:/mnt/pve-VMStorage /mnt/tnvms nfs noauto,x-systemd.automount 0 0
10.250.50.50:/mnt/docker /mnt/compose nfs defaults 0 0
10.250.50.50:/mnt/backup /mnt/backup nfs defaults 0 0

===== TARGETED DATA PATHS =====

/opt  (total: 6.1G)
  total 16
  drwxr-xr-x  4 root    root 4096 2026-04-02 22:12 .
  drwxr-xr-x 20 root    root 4096 2026-03-30 22:49 ..
  drwxr-xr-x 10 lkraven root 4096 2026-04-03 08:44 AIPA
  drwxrwxrwx  6 root    root 4096 2026-04-15 23:28 docker

/opt/docker  (total: 6.0G)
  total 32
  drwxrwxrwx  6 root    root    4096 2026-04-15 23:28 .
  drwxr-xr-x  4 root    root    4096 2026-04-02 22:12 ..
  drwxr-xr-x 21 lkraven lkraven 4096 2026-04-19 22:47 compose
  drwxr-xr-x 10 lkraven lkraven 4096 2026-04-18 18:57 conf
  drwxr-xr-x  7 lkraven lkraven 4096 2025-02-05 19:28 data
  drwxr-xr-x  8 lkraven lkraven 4096 2026-04-15 23:47 .git
  -rw-r--r--  1 lkraven lkraven   14 2024-05-30 18:44 .gitignore
  -rw-r--r--  1 lkraven lkraven   60 2024-05-30 15:33 README.md

/opt/docker/compose  (total: 244K)
  total 88
  drwxr-xr-x 21 lkraven lkraven 4096 2026-04-19 22:47 .
  drwxrwxrwx  6 root    root    4096 2026-04-15 23:28 ..
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-19 22:11 backrest
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-19 00:50 beszel
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-15 23:02 crowdsec
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 18:50 dockge
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-19 00:25 dozzle-hub
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 18:50 gitea
  drwxr-xr-x  2 lkraven lkraven 4096 2025-03-18 22:07 ittools
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 18:50 mailrise
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 18:50 mattermost
  drwxr-xr-x  2 lkraven lkraven 4096 2025-02-05 21:53 openwebui
  -rw-r--r--  1 lkraven lkraven   25 2024-05-30 15:33 README.md
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 18:50 restic
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-19 22:47 rest-server-ana
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 18:50 rustdesk
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-20 14:26 seafile
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-18 18:55 searxng
  drwxr-xr-x  2 lkraven lkraven 4096 2025-02-05 19:29 sillytavern
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-11 13:59 synapse
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 18:50 traefik
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 18:50 vaultwarden

/opt/docker/conf  (total: 3.4M)
  total 40
  drwxr-xr-x 10 lkraven lkraven 4096 2026-04-18 18:57 .
  drwxrwxrwx  6 root    root    4096 2026-04-15 23:28 ..
  drwxr-xr-x 11 lkraven root    4096 2026-04-16 17:56 crowdsec
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 16:16 mailrise
  drwxr-xr-x  2 lkraven lkraven 4096 2024-05-30 16:19 mattermost
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-18 19:22 searxng
  drwxr-xr-x  2 lkraven lkraven 4096 2025-03-18 22:50 sillytavern
  drwxr-xr-x  2 linus   linus   4096 2026-04-15 21:48 synapse
  drwxr-xr-x  3 lkraven lkraven 4096 2024-05-30 16:11 traefik-ana
  drwxr-xr-x  2 lkraven lkraven 4096 2026-04-16 16:28 vaultwarden

/var/lib/docker  (total: 4.0K)

/data  (total: 60K)
  total 12
  drwxr-xr-x  3 root root 4096 2023-06-12 22:33 .
  drwxr-xr-x 20 root root 4096 2026-03-30 22:49 ..
  drwxr-xr-x  4 root root 4096 2023-11-02 17:05 compose

/srv  (total: 4.0K)
  total 8
  drwxr-xr-x  2 root root 4096 2023-04-03 00:06 .
  drwxr-xr-x 20 root root 4096 2026-03-30 22:49 ..


===== DOCKER =====

Server: 20.10.24+dfsg1   Client: 20.10.24+dfsg1

----- docker info -----
Containers:      26 (running 24, paused 0, stopped 2)
Images:          63
Runtimes:        map[io.containerd.runc.v2:{runc [] <nil>} io.containerd.runtime.v1.linux:{runc [] <nil>} runc:{runc [] <nil>}]
Default runtime: runc
Storage driver:  overlay2
Root dir:        /var/lib/docker
Server version:  20.10.24+dfsg1

----- running containers -----
NAMES                    IMAGE                                    STATUS                  PORTS
seafile                  seafileltd/seafile-mc:11.0-latest        Up About a minute       0.0.0.0:9180->80/tcp, :::9180->80/tcp
seafile-mysql            mariadb:10.6                             Up About a minute       3306/tcp
seafile-memcached        memcached:1.6.18                         Up About a minute       11211/tcp
rest-server              restic/rest-server:latest                Up 3 hours (healthy)    0.0.0.0:8000->8000/tcp, :::8000->8000/tcp
backrest                 garethgeorge/backrest:latest             Up 16 hours (healthy)   0.0.0.0:9898->9898/tcp, :::9898->9898/tcp
dockge-dockge-1          louislam/dockge:latest                   Up 19 hours (healthy)   0.0.0.0:5001->5001/tcp, :::5001->5001/tcp
searxng                  searxng/searxng:latest                   Up 26 hours (healthy)   0.0.0.0:9996->8080/tcp, :::9996->8080/tcp
beszel                   henrygd/beszel:latest                    Up 27 hours (healthy)   0.0.0.0:8090->8090/tcp, :::8090->8090/tcp
beszel-agent             henrygd/beszel-agent:latest              Up 27 hours             
dozzle                   amir20/dozzle:latest                     Up 38 hours (healthy)   0.0.0.0:8088->8080/tcp, :::8088->8080/tcp
blocklist-mirror         crowdsecurity/blocklist-mirror:latest    Up 3 days               0.0.0.0:41412->41412/tcp, :::41412->41412/tcp
vaultwarden              vaultwarden/server:latest                Up 3 days (healthy)     0.0.0.0:9080->80/tcp, :::9080->80/tcp
crowdsec                 crowdsecurity/crowdsec:latest            Up 3 days               
traefik                  traefik:latest                           Up 3 days               0.0.0.0:80->80/tcp, :::80->80/tcp, 0.0.0.0:443->443/tcp, :::443->443/tcp, 0.0.0.0:8380->8080/tcp, :::8380->8080/tcp
gitea                    gitea/gitea:latest                       Up 3 days               0.0.0.0:3000->3000/tcp, :::3000->3000/tcp, 0.0.0.0:222->22/tcp, :::222->22/tcp
element-web              vectorim/element-web:v1.11.80            Up 4 days               80/tcp
synapse                  matrixdotorg/synapse:v1.120.0            Up 4 days (healthy)     8008-8009/tcp, 8448/tcp
synapse-db               postgres:16-alpine                       Up 4 days (healthy)     5432/tcp
sillytavern              ghcr.io/sillytavern/sillytavern:latest   Up 2 weeks              0.0.0.0:8100->8000/tcp, :::8100->8000/tcp
openwebui-open-webui-1   ghcr.io/open-webui/open-webui:main       Up 2 weeks (healthy)    0.0.0.0:3100->8080/tcp, :::3100->8080/tcp
hbbs                     rustdesk/rustdesk-server:latest          Up 2 weeks              
hbbr                     rustdesk/rustdesk-server:latest          Up 2 weeks              
it-tools                 corentinth/it-tools:latest               Up 2 weeks              0.0.0.0:8780->80/tcp, :::8780->80/tcp
mailrise                 yoryan/mailrise:latest                   Up 2 weeks              0.0.0.0:8025->8025/tcp, :::8025->8025/tcp

----- all containers -----
NAMES                    IMAGE                                    STATUS
seafile                  seafileltd/seafile-mc:11.0-latest        Up About a minute
seafile-mysql            mariadb:10.6                             Up About a minute
seafile-memcached        memcached:1.6.18                         Up About a minute
rest-server              restic/rest-server:latest                Up 3 hours (healthy)
backrest                 garethgeorge/backrest:latest             Up 16 hours (healthy)
dockge-dockge-1          louislam/dockge:latest                   Up 19 hours (healthy)
searxng                  searxng/searxng:latest                   Up 26 hours (healthy)
beszel                   henrygd/beszel:latest                    Up 27 hours (healthy)
beszel-agent             henrygd/beszel-agent:latest              Up 27 hours
dozzle                   amir20/dozzle:latest                     Up 38 hours (healthy)
blocklist-mirror         crowdsecurity/blocklist-mirror:latest    Up 3 days
vaultwarden              vaultwarden/server:latest                Up 3 days (healthy)
crowdsec                 crowdsecurity/crowdsec:latest            Up 3 days
traefik                  traefik:latest                           Up 3 days
gitea                    gitea/gitea:latest                       Up 3 days
simple-service-bar       traefik/whoami                           Created
simple-service-foo       traefik/whoami                           Created
element-web              vectorim/element-web:v1.11.80            Up 4 days
synapse                  matrixdotorg/synapse:v1.120.0            Up 4 days (healthy)
synapse-db               postgres:16-alpine                       Up 4 days (healthy)
sillytavern              ghcr.io/sillytavern/sillytavern:latest   Up 2 weeks
openwebui-open-webui-1   ghcr.io/open-webui/open-webui:main       Up 2 weeks (healthy)
hbbs                     rustdesk/rustdesk-server:latest          Up 2 weeks
hbbr                     rustdesk/rustdesk-server:latest          Up 2 weeks
it-tools                 corentinth/it-tools:latest               Up 2 weeks
mailrise                 yoryan/mailrise:latest                   Up 2 weeks

----- networks -----
NAME                       DRIVER    SCOPE
bridge                     bridge    local
host                       host      local
it-tools_default           bridge    local
ittools_default            bridge    local
mailrise_default           bridge    local
none                       null      local
portainer_default          bridge    local
synapse_synapse-internal   bridge    local
traefik-net                bridge    local

----- networks (external, non-default — worth knowing for compose external: true) -----
it-tools_default
ittools_default
mailrise_default
portainer_default
synapse_synapse-internal
traefik-net

----- named volumes -----
VOLUME NAME                                                        DRIVER
0d2873a4373bfab9214f37bc8ad46d0ed5a90805fffa8dbef7b915493da66a7b   local
1a587fdaf8f4f022cef113ce59f0ce171fcf2247c52f28df1f4e461985ff6a4f   local
5b532eb6c5bb5a718a68824a004c9eee9ffb6d726a19bdf066ecb6348a6c697c   local
6b7b248964ce54c151cf57a1f44cfc095d9c2bd1a9844eba2e05ad4e143e05ad   local
9d1360a12bd6ca0b11d52b02a00248fd80712667510453b4ca882656798c69c8   local
28ae9933a241df783c23ff0de09882078851bef60d3440dad9243b5ba8766985   local
53bf6d927badb5904b71d4180d1f05ccac2a195b7362206a8b0ffece5771aa9a   local
065fbcc9d093988c8a8c005688f119d87855407957745d82dee4ff0c4c615ea6   local
76ab976f6fb5f8f5cd322d32975206ae490f6f4644bfa315632e6ef6c3da54eb   local
88b9750e458794db88b0694b5b9dd5bbe595651355f3e552bd84cbbe856fbc95   local
207f0f98a462e2b0a2da5176be52704c3aba26039f47c4ccc685619e81bf7a7a   local
backrest_backrest_cache                                            local
backrest_backrest_config                                           local
backrest_backrest_data                                             local
backrest_backrest_tmp                                              local
beszel_beszel_agent_data                                           local
beszel_beszel_data                                                 local
crowdsec_crowdsec-data                                             local
crowdsec_traefik-logs                                              local
dockge_dockge_data                                                 local
dozzle-hub_dozzle_data                                             local
edf9fc3909e2faa49c147b4029db703466116f06d9fe2dc87d902bc27c6b77a0   local
gitea_gitea_data                                                   local
komodo_repo-cache                                                  local
mattermost_mattermost_data                                         local
openwebui_open-webui                                               local
rustdesk_rustdesk_data                                             local
seafile_seafile_datastore                                          local
seafile_seafile_db                                                 local
sillytavern_sillytavern_data                                       local
sillytavern_sillytavern_extensions                                 local
sillytavern_sillytavern_plugins                                    local
synapse-data                                                       local
synapse_synapse-data                                               local
synapse_synapse-db-data                                            local
traefik_traefik-logs                                               local
vaultwarden_vaultwarden_data                                       local

----- compose projects currently running -----
backrest
beszel
crowdsec
dockge
dozzle-hub
gitea
ittools
mailrise
openwebui
rest-server-ana
rustdesk
seafile
searxng
sillytavern
synapse
traefik
vaultwarden

===== COMPOSE FILES (/opt/docker/compose/) =====


>>> /opt/docker/compose/backrest/compose.yaml
# Backrest — web UI over restic repositories.
#
# Role here: single central viewer for every host's restic repo on both
# site-local S3 endpoints (TrueNAS at ana, Synology at nh3). Per-host
# `restic` runs will still be driven by systemd timers on each host; this
# stack is how we see what ran, browse snapshots, and restore.
#
# Repos and S3 credentials are configured in the Backrest UI after first
# boot — nothing baked into this file. Data (its own SQLite + queue) lives
# in a named volume so the config survives container recreation.
#
# All tunables live in .env — edit that, not this file.

services:
  backrest:
    image: garethgeorge/backrest:${BACKREST_VERSION}
    container_name: backrest
    hostname: backrest
    restart: unless-stopped
    ports:
      - ${BACKREST_PORT}:9898
    volumes:
      - backrest_data:/data
      - backrest_config:/config
      - backrest_cache:/cache
      - backrest_tmp:/tmp
    environment:
      - BACKREST_DATA=/data
      - BACKREST_CONFIG=/config/config.json
      - XDG_CACHE_HOME=/cache
      - TMPDIR=/tmp
      - TZ=${TZ:-America/Los_Angeles}
      - BACKREST_PORT=0.0.0.0:9898
    healthcheck:
      test:
        - CMD
        - wget
        - -qO-
        - http://localhost:9898/
      interval: 30s
      timeout: 10s
      retries: 3
      start_period: 15s
    networks:
      - tnet
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=Backrest
      - homepage.icon=mdi-backup-restore
      - homepage.description=Restic snapshot viewer / restore UI
      - homepage.href=http://10.250.50.70:${BACKREST_PORT}
volumes:
  backrest_data: null
  backrest_config: null
  backrest_cache: null
  backrest_tmp: null
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/beszel/compose.yaml
# Beszel — lightweight server/container monitoring.
#
# Hub: single web UI with the SQLite store. Agents: per-host metric collectors
# that the hub pulls from over SSH.
#
# Multi-host layout via compose profiles:
#   COMPOSE_PROFILES=hub          → hub only        (ana-docker)
#   COMPOSE_PROFILES=hub,agent    → hub + local agent on the same host
#   COMPOSE_PROFILES=agent        → agent only      (ana-ml2)
#
# The agent uses network_mode: host so it sees real host CPU/mem/net/disk
# counters rather than container-scoped ones — that's why it can't share
# the tnet network with the hub.
#
# All tunables live in .env — edit that, not this file.

services:
  beszel:
    image: henrygd/beszel:${BESZEL_VERSION}
    container_name: beszel
    profiles:
      - hub
    restart: unless-stopped
    ports:
      - ${BESZEL_PORT}:8090
    volumes:
      - beszel_data:/beszel_data
    networks:
      - tnet
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=Beszel
      - homepage.icon=mdi-chart-line
      - homepage.description=Server + container monitoring
      - homepage.href=http://10.250.50.70:${BESZEL_PORT}
    healthcheck:
      # The URL is relative to the container, not the host
      test: ['CMD', '/beszel', 'health', '--url', 'http://localhost:8090']
      start_period: 5s # Check 5 seconds after the container starts
      interval: 120s # Then check every 120 seconds after that
      
  beszel-agent:
    image: henrygd/beszel-agent:${BESZEL_VERSION}
    container_name: beszel-agent
    profiles:
      - agent
    restart: unless-stopped
    network_mode: host
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - beszel_agent_data:/var/lib/beszel-agent
    environment:
      - PORT=${BESZEL_AGENT_PORT:-45876}
      - KEY=${BESZEL_HUB_KEY}
      - HUB_URL=${HUB_URL}
      - TOKEN=${BESZEL_TOKEN}
      - EXTRA_FILESYSTEMS=${BESZEL_EXTRA_FS:-}
volumes:
  beszel_data: null
  beszel_agent_data: null
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/crowdsec/compose.yaml
# /opt/docker/compose/crowdsec/compose.yaml
#
# CrowdSec — collaborative intrusion prevention
#
# Agent: reads Docker container logs, parses events, makes decisions
# Bouncing: handled by CrowdSec Traefik plugin inside the Traefik container
#           (no separate bouncer container needed)
#
# Protected services (via Traefik middleware):

services:
  crowdsec:
    image: crowdsecurity/crowdsec:latest
    container_name: crowdsec
    restart: unless-stopped
    security_opt:
      - no-new-privileges:true
    volumes:
      - crowdsec-data:/var/lib/crowdsec/data
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - /opt/docker/conf/crowdsec:/etc/crowdsec
    environment:
      - COLLECTIONS=crowdsecurity/linux crowdsecurity/traefik LePresidente/gitea
      - TZ=${TZ:-America/Los_Angeles}
      - CROWDSEC_LAPI_BIND=0.0.0.0:8080
      - DOCKER_API_VERSION=1.41
    networks:
      - traefik-net
  blocklist-mirror:
    image: crowdsecurity/blocklist-mirror:latest
    container_name: blocklist-mirror
    restart: unless-stopped
    ports:
      - 41412:41412
    volumes:
      - /opt/docker/conf/crowdsec/blocklist-mirror.yaml:/etc/crowdsec/bouncers/crowdsec-blocklist-mirror.yaml:ro
    networks:
      - traefik-net
volumes:
  crowdsec-data: null
networks:
  traefik-net:
    external: true

>>> /opt/docker/compose/dockge/compose.yaml
services:
  dockge:
    image: louislam/dockge:latest
    restart: unless-stopped
    ports:
      # Host Port : Container Port
      - 5001:5001
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - dockge_data:/app/data
      - /opt/docker/compose:/opt/docker/compose
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=Dockge
      - homepage.icon=si-portainer
      - homepage.description=Docker
      - homepage.href=http://10.250.50.70:5001
    environment:
      # Tell Dockge where is your stacks directory
      - DOCKGE_STACKS_DIR=/opt/docker/compose
    networks:
      - tnet

volumes:
  dockge_data: null
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/dozzle-hub/compose.yaml
# Dozzle — container log viewer.
#
# Multi-host layout via compose profiles:
#   COMPOSE_PROFILES=hub   → runs the web UI (deploy on ana-docker)
#   COMPOSE_PROFILES=agent → runs the remote agent (deploy on ana-ml2)
#
# Same compose.yaml on both servers; per-host `.env` picks the profile.
#
# All tunables live in .env — edit that, not this file.

services:
  dozzle:
    image: amir20/dozzle:${DOZZLE_VERSION}
    container_name: dozzle
    profiles:
      - hub
    restart: unless-stopped
    ports:
      - ${DOZZLE_PORT}:8080
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - dozzle_data:/data
    environment:
      - DOZZLE_HOSTNAME=${DOZZLE_HOSTNAME}
      - DOZZLE_REMOTE_AGENT=${DOZZLE_REMOTE_AGENT:-}
      - DOZZLE_AUTH_PROVIDER=${DOZZLE_AUTH_PROVIDER:-none}
      - DOZZLE_USERNAME=${DOZZLE_USERNAME:-}
      - DOZZLE_PASSWORD=${DOZZLE_PASSWORD:-}
    healthcheck:
      test:
        - CMD
        - /dozzle
        - healthcheck
      interval: 30s
      timeout: 10s
      retries: 3
      start_period: 15s
    networks:
      - tnet
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=Dozzle
      - homepage.icon=mdi-text-box-search
      - homepage.description=Container logs (ana-docker + ana-ml2)
      - homepage.href=http://10.250.50.70:${DOZZLE_PORT}
  dozzle-agent:
    image: amir20/dozzle:${DOZZLE_VERSION}
    container_name: dozzle-agent
    profiles:
      - agent
    restart: unless-stopped
    command: agent
    ports:
      - ${DOZZLE_AGENT_BIND:-0.0.0.0}:${DOZZLE_AGENT_PORT}:7007
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - dozzle_agent_data:/data
    environment:
      - DOZZLE_HOSTNAME=${DOZZLE_HOSTNAME}
    networks:
      - tnet
volumes:
  dozzle_data: null
  dozzle_agent_data: null
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/gitea/compose.yaml
services:
  server:
    image: gitea/gitea:latest
    container_name: gitea
    environment:
      - USER_UID=1000
      - USER_GID=1000
      - GITEA__database__DB_TYPE=postgres
      - GITEA__database__HOST=${DB_IP}:5432
      - GITEA__database__NAME=gitea
      - GITEA__database__USER=gitea
      - GITEA__database__PASSWD=gitea
      - GITEA__service__DISABLE_REGISTRATION=true
      - GITEA__log__MODE=console
      - GITEA__log__LEVEL=Info
      - GITEA__log__ROUTER=console
    restart: unless-stopped
    volumes:
      - gitea_data:/data
      - /etc/timezone:/etc/timezone:ro
      - /etc/localtime:/etc/localtime:ro
    ports:
      - 3000:3000
      - 222:22
    labels:
      - homepage.group=Apps
      - homepage.name=Gitea
      - homepage.icon=si-gitea
      - homepage.description=Git Repo (ana)
      - homepage.href=https://gitea.phasefinal.com
      - traefik.enable=true
      - traefik.http.routers.gitea.tls=true
      - traefik.http.routers.gitea.rule=Host(`gitea.phasefinal.com`)
      - traefik.http.routers.gitea.tls.certresolver=anaprod
      - traefik.http.services.gitea.loadbalancer.server.port=3000
      - traefik.http.routers.gitea.middlewares=crowdsec@file
      - crowdsec.labels.type=gitea
    networks:
      - tnet
networks:
  tnet:
    name: traefik-net
    external: true
volumes:
  gitea_data: null

>>> /opt/docker/compose/ittools/compose.yaml
services:
  it-tools:
    image: corentinth/it-tools:latest
    container_name: it-tools
    restart: unless-stopped
    ports:
      - "8780:80"
    labels:
      - homepage.group=Apps
      - homepage.name=IT Tools
      - homepage.icon=mdi-tools
      - homepage.description=IT Dev Tools
      - homepage.href=http://10.250.50.70:8780
>>> /opt/docker/compose/mailrise/compose.yaml
#version: '3'
services:
  mailrise:
    image: yoryan/mailrise:latest
    container_name: mailrise
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=Mailrise
      - homepage.icon=mdi-mail
      - homepage.description=Mail to Notification Agent
      - homepage.href=http://10.250.50.70:8025
    volumes:
      - /opt/docker/conf/mailrise/mailrise.conf:/etc/mailrise.conf:ro
    restart: unless-stopped
    environment:
      - USER=1000:1000
    ports:
      - 8025:8025
networks: {}

>>> /opt/docker/compose/mattermost/compose.yaml
#version: "2.4"

services:
  mattermost:
    image: mattermost/mattermost-team-edition:latest
    restart: unless-stopped
    tmpfs:
      - /tmp
    volumes:
#      - mattermost_data:/mm
      - mattermost_data:/mattermost
#      - /opt/docker/conf/mattermost:/mattermost/config
#      - /opt/docker/data/mattermost/data:/mattermost/data
#     - /opt/docker/data/mattermost/logs:/mattermost/logs
#     - /opt/docker/data/mattermost/plugins:/mattermost/plugins
#      - /opt/docker/data/mattermost/client/plugins:/mattermost/client/plugins
#      - /opt/docker/data/mattermost/bleve-indexes:/mattermost/bleve-indexes
    environment:
      TZ: America/Los_Angeles
      DOMAIN: mm.phasefinal.com
      MM_SQLSETTINGS_DRIVERNAME: postgres
      MM_SQLSETTINGS_DATASOURCE: ${DATASOURCE}
    ports:
      - 8065:8065
      - 8443:8443/udp
    user: 1000:1000
    labels:
      - homepage.group=Apps
      - homepage.name=MatterMost
      - homepage.icon=si-mattermost
      - homepage.description=Chat Application (ana)
      - homepage.href=https://mm.phasefinal.com
      - traefik.enable=true
      - traefik.http.routers.mattermost.tls=true
      - traefik.http.routers.mattermost.rule=Host(`mm.phasefinal.com`)
      - traefik.http.routers.mattermost.tls.certresolver=anaprod
      - traefik.http.services.mattermost.loadbalancer.server.port=8065
    networks:
      - tnet
networks:
  tnet:
    name: traefik-net
    external: true
volumes:
  mattermost_data: null

>>> /opt/docker/compose/openwebui/compose.yaml
version: "3"
services:
  open-webui:
    ports:
      - 3100:8080
    volumes:
      - open-webui:/app/backend/data
    restart: unless-stopped
    image: ghcr.io/open-webui/open-webui:main
    labels:
      - homepage.group=AI Systems
      - homepage.name=Open WebUI
      - homepage.icon=mdi-chat
      - homepage.description=Open WebUI Chat - ana - 3100
      - homepage.href=http://10.250.50.70:3100
    networks:
      - tnet
    env_file:
      - .env
volumes:
  open-webui: null
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/restic/compose.yaml
# ignored : docker pull restic/rest-server:latest

#version: "3.3"
services:
  rest-server:
    ports:
      - 8000:8000
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=Restic
      - homepage.icon=mdi-cloud-upload
      - homepage.description=Restic Backup Server (8000:ana)
      - homepage.href=http://10.250.50.70:8000
    volumes:
      - /mnt/backup/restic/repo/ana:/data
    container_name: rest_server
    image: restic/rest-server
    networks:
      - tnet
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/rest-server-ana/compose.yaml
# rest-server (Anaheim) — restic backup target for the fleet.
#
# Deploys to ana-docker. Data dir is on the TrueNAS NFS mount
# (/mnt/backup/restic/repo/ana) so snapshots on the NAS side protect the
# backup blobs themselves.
#
# Mirrors stacks/rest-server-nh3/ in every meaningful way — same auth
# model, same on-disk layout, same operational semantics — so each client
# host uses an identical URL shape against either endpoint:
#
#   rest:http://<user>:<pw>@10.100.50.50:8000/<user>/     (NH3 Synology)
#   rest:http://<user>:<pw>@10.250.50.70:8000/<user>/     (this stack)
#
# Auth model:
#   --private-repos : URL path must start with /<user>/ and the HTTP
#                     basic-auth user must match. Per-host repos are
#                     strictly isolated.
#   --append-only   : on-disk data can be added but not removed or
#                     rewritten; a compromised host can't wipe its own
#                     history. Prune requires disabling this (see README).
#
# Credentials come from /data/.htpasswd — see README for populating it.
#
# All tunables live in .env — edit that, not this file.

services:
  rest-server:
    image: restic/rest-server:${REST_SERVER_VERSION}
    container_name: rest-server
    restart: unless-stopped
    # Run as the UID that owns the NFS-backed data dir, so file I/O
    # is not subject to NFS root_squash. On ana-docker this is lkraven (1000).
    user: ${REST_UID:-1000}:${REST_GID:-1000}
    ports:
      - ${REST_PORT}:8000
    volumes:
      - ${DATA_DIR}:/data
    environment:
      - OPTIONS=--private-repos --append-only --prometheus ${EXTRA_OPTIONS:-}
      - TZ=${TZ:-America/Los_Angeles}
    healthcheck:
      test: ["CMD", "nc", "-z", "localhost", "8000"]
      interval: 30s
      timeout: 10s
      retries: 3
      start_period: 15s
    networks:
      - tnet
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=Restic (rest-server)
      - homepage.icon=mdi-cloud-upload
      - homepage.description=Anaheim restic endpoint (data on TrueNAS NFS)
      - homepage.href=http://10.250.50.70:${REST_PORT}
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/rustdesk/compose.yaml
version: "3"
services:
  hbbs:
    container_name: hbbs
    image: rustdesk/rustdesk-server:latest
    command: hbbs
    volumes:
      - rustdesk_data:/root
      #- /opt/docker/data/rustdesk:/root
    network_mode: host
    depends_on:
      - hbbr
    restart: unless-stopped
  hbbr:
    container_name: hbbr
    image: rustdesk/rustdesk-server:latest
    command: hbbr
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=Rustdesk
      - homepage.icon=si-rustdesk
      - homepage.description=Rustdesk Relay Server (ana)
      - homepage.href=https://rustdesk.phasefinal.com
    volumes:
      - rustdesk_data:/root
      #- /opt/docker/data/rustdesk:/root
    network_mode: host
    restart: unless-stopped
networks: {}
volumes:
  rustdesk_data: null

>>> /opt/docker/compose/seafile/compose.yaml
# version: '2.0'
services:
  db:
    image: mariadb:10.6
    container_name: seafile-mysql
    environment:
      - MYSQL_ROOT_PASSWORD=${DB_ROOT_PW}
      - MYSQL_LOG_CONSOLE=true
    volumes:
      - seafile_db:/var/lib/mysql # Requested, specifies the path to MySQL data persistent store.
    networks:
      - tnet
  memcached:
    image: memcached:1.6.18
    container_name: seafile-memcached
    entrypoint: memcached -m 256
    networks:
      - tnet
  seafile:
    image: seafileltd/seafile-mc:11.0-latest
    container_name: seafile
    ports:
      - 9180:80
    volumes:
      - seafile_datastore:/shared # Requested, specifies the path to Seafile data persistent store.
    environment:
      - DB_HOST=db
      - DB_ROOT_PASSWD=${DB_ROOT_PW}
      - TIME_ZONE=America/Los_Angeles
      - SEAFILE_ADMIN_EMAIL=${SEAFILE_ADMIN_EMAIL}
      - SEAFILE_ADMIN_PASSWORD=${SEAFILE_ADMIN_PW}
    depends_on:
      - db
      - memcached
    labels:
      - homepage.group=Apps
      - homepage.name=SeaFile
      - homepage.icon=mdi-sync-circle
      - homepage.description=File Sync Service (ana)
      - homepage.href=https://seafile.phasefinal.com
      - traefik.enable=true
      - traefik.http.routers.seafile.tls=true
      - traefik.http.routers.seafile.rule=Host(`seafile.phasefinal.com`)
      - traefik.http.routers.seafile.tls.certresolver=anaprod
    networks:
      - tnet
    env_file:
      - .env
volumes:
  seafile_db: null
  seafile_datastore: null
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/searxng/compose.yaml
services:
  searxng:
    image: searxng/searxng:latest
    container_name: searxng
    restart: unless-stopped
    # ------------------------------------------------------------------
    # Port binding — 9996 on all interfaces.
    # Change to "127.0.0.1:9996:8080" to restrict to localhost only.
    # Traefik handles public routing and TLS via the labels below.
    # ------------------------------------------------------------------
    ports:
      - 9996:8080
    # ------------------------------------------------------------------
    # Volumes
    #   Config: settings.yml bind-mounted read-only into the container.
    volumes:
      - /opt/docker/conf/searxng/searxng-settings.yml:/etc/searxng/settings.yml:ro
    # ------------------------------------------------------------------
    # Environment — see https://docs.searxng.org/admin/settings/index.html
    #   SEARXNG_SECRET  — required for cryptographic signing (cookies, etc.)
    #   BASE_URL        — public URL SearXNG reports in pages/RSS/OPDS
    #   INSTANCE_NAME   — shown in the page title / footer
    # ------------------------------------------------------------------
    environment:
      - SEARXNG_SECRET=${SEARXNG_SECRET}
      - BASE_URL=https://searxng.pfi.local/
      - INSTANCE_NAME=SearXNG
    # ------------------------------------------------------------------
    # Resource limits — tune for VM 102's available RAM/CPU
    # ------------------------------------------------------------------
    deploy:
      resources:
        limits:
          memory: 512M
          cpus: "1.0"
        reservations:
          memory: 128M
    # ------------------------------------------------------------------
    # Health check — SearXNG /healthz is the canonical liveness probe.
    # ------------------------------------------------------------------
    healthcheck:
      test:
        - CMD
        - wget
        - --no-verbose
        - --tries
        - --spider
        - http://localhost:8080/healthz
      interval: 30s
      timeout: 10s
      retries: 3
      start_period: 15s
    networks:
      - tnet
    labels:
      # Traefik configuration — auto-discovery via Docker provider
      - traefik.enable=true
      - traefik.http.routers.searxng.rule=Host(`searxng.pfi.local`)
      - traefik.http.routers.searxng.entrypoints=websecure
      - traefik.http.routers.searxng.tls=true
      - traefik.http.routers.searxng.service=searxng
      - traefik.http.services.searxng.loadbalancer.server.port=8080
networks:
  tnet:
    name: traefik-net
    external: true

>>> /opt/docker/compose/sillytavern/compose.yaml
version: "3"
services:
  sillytavern:
    build: ..
    container_name: sillytavern
    hostname: sillytavern
    image: ghcr.io/sillytavern/sillytavern:latest
    ports:
      - 8100:8000
    volumes:
      - sillytavern_data:/home/node/app/data
      - sillytavern_plugins:/home/node/app/plugins
      - sillytavern_extensions:/home/node/app/public/scripts/extensions/third-party
      - /opt/docker/conf/sillytavern:/home/node/app/config
    #      - /opt/docker/data/sillytavern/data:/home/node/app/data
    #      - /opt/docker/data/sillytavern/plugins:/home/node/app/plugins
    #      - /opt/docker/data/sillytavern/extensions:/home/node/app/public/scripts/extensions/third-party
    restart: unless-stopped
    labels:
      - homepage.group=AI Systems
      - homepage.name=Silly Tavern
      - homepage.icon=mdi-chat
      - homepage.description=Silly Tavern AI - ANA-Docker 8100
      - homepage.href=http://10.250.50.70:8100
    networks:
      - tnet
networks:
  tnet:
    name: traefik-net
    external: true
volumes:
  sillytavern_data: null
  sillytavern_plugins: null
  sillytavern_extensions: null

>>> /opt/docker/compose/synapse/compose.yaml
# ==============================================================================
# Matrix Synapse Stack — VM-102 (10.250.50.70)
# Domain: matrix.phasefinal.com
#
# Deploy: /opt/docker/compose/synapse/compose.yaml
# Config: /opt/docker/conf/synapse/homeserver.yaml
#
# Services:
#   1. synapse-db    — Postgres 16 (internal only)
#   2. synapse       — Matrix Synapse homeserver (port 8008)
#   3. element-web   — Element Web client (port 8080)
#
# Stack uses traefik-net (tnet) for reverse proxy / TLS termination.
# Cert resolver: anaprod (matches existing VM-102 convention)
# ==============================================================================

services:
  # ---------------------------------------------------------------------------
  # Postgres database for Synapse
  # ---------------------------------------------------------------------------
  synapse-db:
    image: postgres:16-alpine
    container_name: synapse-db
    restart: unless-stopped
    environment:
      POSTGRES_DB: synapse
      POSTGRES_USER: synapse
      POSTGRES_PASSWORD: MOV0AHc26hHw9jDkjgIZqLb1zmY0um0v
      POSTGRES_INITDB_ARGS: --lc-collate=C --lc-ctype=C --encoding=UTF8
    volumes:
      - synapse-db-data:/var/lib/postgresql/data
    networks:
      - synapse-internal
    healthcheck:
      test:
        - CMD-SHELL
        - pg_isready -U synapse -d synapse
      interval: 10s
      timeout: 5s
      retries: 5
  # ---------------------------------------------------------------------------
  # Matrix Synapse homeserver
  # ---------------------------------------------------------------------------
  synapse:
    image: matrixdotorg/synapse:v1.120.0
    container_name: synapse
    restart: unless-stopped
    depends_on:
      synapse-db:
        condition: service_healthy
    volumes:
      - /opt/docker/conf/synapse/homeserver.yaml:/data/homeserver.yaml:ro
      - synapse-data:/data
      - /opt/docker/conf/synapse/aipa_appservice.yaml:/conf/aipa_appservice.yaml:ro
    networks:
      - tnet
      - synapse-internal
    labels:
      - traefik.enable=true
      - traefik.http.routers.synapse.rule=Host(`matrix.phasefinal.com`)
      - traefik.http.routers.synapse.tls=true
      - traefik.http.routers.synapse.tls.certresolver=anaprod
      - traefik.http.services.synapse.loadbalancer.server.port=8008
  # ---------------------------------------------------------------------------
  # Element Web client
  # ---------------------------------------------------------------------------
  element-web:
    image: vectorim/element-web:v1.11.80
    container_name: element-web
    restart: unless-stopped
    depends_on:
      - synapse
    volumes:
      - /opt/docker/conf/synapse/element-config.json:/app/config.json:ro
    networks:
      - tnet
    labels:
      - traefik.enable=true
      - traefik.http.routers.element.rule=Host(`chat.phasefinal.com`)
      - traefik.http.routers.element.tls=true
      - traefik.http.routers.element.tls.certresolver=anaprod
      - traefik.http.services.element.loadbalancer.server.port=80
networks:
  synapse-internal:
    driver: bridge
  tnet:
    name: traefik-net
    external: true
# =============================================================================
# Volumes
# =============================================================================
volumes:
  synapse-db-data: null
  synapse-data: null

>>> /opt/docker/compose/traefik/compose.yaml
services:
  traefik:
    image: traefik:latest
    container_name: traefik
    command:
      - --configFile=/etc/traefik/traefik.yml
    ports:
      - 80:80
      - 8380:8080
      - 443:443
    labels:
      - homepage.group=PFI-ANA
      - homepage.name=traefik
      - homepage.icon=si-traefikproxy
      - homepage.sitemonitor=http://10.250.50.70:8380
      - homepage.href=http://10.250.50.70:8380
      - homepage.widget.type=traefik
      - homepage.widget.url=http://10.250.50.70:8380
      - crowdsec.labels.type=traefik
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - /opt/docker/conf/traefik-ana/config:/etc/traefik
      - /opt/docker/conf/traefik-ana/acme.json:/acme.json
      - traefik-logs:/var/log/traefik # Important for CrowdSec
    networks:
      - tnet
    restart: unless-stopped
networks:
  tnet:
    name: traefik-net
    external: true
volumes:
  traefik-logs: null

>>> /opt/docker/compose/vaultwarden/compose.yaml
#version: '3'
services:
  vaultwarden:
    image: vaultwarden/server:latest
    container_name: vaultwarden
    volumes:
      - vaultwarden_data:/data
      - /opt/docker/conf/vaultwarden/config.json:/data/config.json
      #- /opt/docker/data/vaultwarden:/data
    ports:
      - 9080:80
    restart: unless-stopped
    labels:
      - homepage.group=Apps
      - homepage.name=Vaultwarden
      - homepage.icon=si-bitwarden
      - homepage.description=Password Vault (ana)
      - homepage.sitemonitor=https://vaultwarden.phasefinal.com
      - homepage.href=https://vaultwarden.phasefinal.com
      - traefik.enable=true
      - traefik.http.routers.vaultwarden.tls=true
      - traefik.http.routers.vaultwarden.rule=Host(`vaultwarden.phasefinal.com`)
      - traefik.http.routers.vaultwarden.tls.certresolver=anaprod
      - crowdsec.labels.type=VaultWarden
    networks:
      - tnet
    env_file:
      - .env
networks:
  tnet:
    name: traefik-net
    external: true
volumes:
  vaultwarden_data: null

===== CONFIG LAYOUT (/opt/docker/conf/ — top 200 entries) =====

/opt/docker/conf
/opt/docker/conf/crowdsec
/opt/docker/conf/crowdsec/acquis.d
/opt/docker/conf/crowdsec/acquis.yaml
/opt/docker/conf/crowdsec/blocklist-mirror.yaml
/opt/docker/conf/crowdsec/collections
/opt/docker/conf/crowdsec/collections/base-http-scenarios.yaml
/opt/docker/conf/crowdsec/collections/gitea.yml
/opt/docker/conf/crowdsec/collections/http-cve.yaml
/opt/docker/conf/crowdsec/collections/linux.yaml
/opt/docker/conf/crowdsec/collections/sshd.yaml
/opt/docker/conf/crowdsec/collections/traefik.yaml
/opt/docker/conf/crowdsec/collections/vaultwarden.yml
/opt/docker/conf/crowdsec/collections/whitelist-good-actors.yaml
/opt/docker/conf/crowdsec/config.yaml
/opt/docker/conf/crowdsec/console.yaml
/opt/docker/conf/crowdsec/contexts
/opt/docker/conf/crowdsec/contexts/bf_base.yaml
/opt/docker/conf/crowdsec/contexts/http_base.yaml
/opt/docker/conf/crowdsec/dev.yaml
/opt/docker/conf/crowdsec/hub
/opt/docker/conf/crowdsec/hub/collections
/opt/docker/conf/crowdsec/hub/collections/crowdsecurity
/opt/docker/conf/crowdsec/hub/collections/Dominic-Wagner
/opt/docker/conf/crowdsec/hub/collections/LePresidente
/opt/docker/conf/crowdsec/hub/contexts
/opt/docker/conf/crowdsec/hub/contexts/crowdsecurity
/opt/docker/conf/crowdsec/hub/.index.json
/opt/docker/conf/crowdsec/hub/parsers
/opt/docker/conf/crowdsec/hub/parsers/s00-raw
/opt/docker/conf/crowdsec/hub/parsers/s01-parse
/opt/docker/conf/crowdsec/hub/parsers/s02-enrich
/opt/docker/conf/crowdsec/hub/postoverflows
/opt/docker/conf/crowdsec/hub/postoverflows/s00-enrich
/opt/docker/conf/crowdsec/hub/postoverflows/s01-whitelist
/opt/docker/conf/crowdsec/hub/scenarios
/opt/docker/conf/crowdsec/hub/scenarios/crowdsecurity
/opt/docker/conf/crowdsec/hub/scenarios/Dominic-Wagner
/opt/docker/conf/crowdsec/hub/scenarios/LePresidente
/opt/docker/conf/crowdsec/hub/scenarios/ltsich
/opt/docker/conf/crowdsec/local_api_credentials.yaml
/opt/docker/conf/crowdsec/notifications
/opt/docker/conf/crowdsec/notifications/email.yaml
/opt/docker/conf/crowdsec/notifications/file.yaml
/opt/docker/conf/crowdsec/notifications/http.yaml
/opt/docker/conf/crowdsec/notifications/sentinel.yaml
/opt/docker/conf/crowdsec/notifications/slack.yaml
/opt/docker/conf/crowdsec/notifications/splunk.yaml
/opt/docker/conf/crowdsec/online_api_credentials.yaml
/opt/docker/conf/crowdsec/parsers
/opt/docker/conf/crowdsec/parsers/s00-raw
/opt/docker/conf/crowdsec/parsers/s00-raw/cri-logs.yaml
/opt/docker/conf/crowdsec/parsers/s00-raw/docker-logs.yaml
/opt/docker/conf/crowdsec/parsers/s00-raw/syslog-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse
/opt/docker/conf/crowdsec/parsers/s01-parse/gitea-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse/sshd-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse/sshd-success-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse/traefik-logs.yaml
/opt/docker/conf/crowdsec/parsers/s01-parse/vaultwarden-logs.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich
/opt/docker/conf/crowdsec/parsers/s02-enrich/dateparse-enrich.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich/geoip-enrich.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich/http-logs.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich/public-dns-allowlist.yaml
/opt/docker/conf/crowdsec/parsers/s02-enrich/whitelists.yaml
/opt/docker/conf/crowdsec/patterns
/opt/docker/conf/crowdsec/patterns/aws
/opt/docker/conf/crowdsec/patterns/bacula
/opt/docker/conf/crowdsec/patterns/bro
/opt/docker/conf/crowdsec/patterns/cowrie_honeypot
/opt/docker/conf/crowdsec/patterns/exim
/opt/docker/conf/crowdsec/patterns/firewalls
/opt/docker/conf/crowdsec/patterns/haproxy
/opt/docker/conf/crowdsec/patterns/java
/opt/docker/conf/crowdsec/patterns/junos
/opt/docker/conf/crowdsec/patterns/linux-syslog
/opt/docker/conf/crowdsec/patterns/mcollective
/opt/docker/conf/crowdsec/patterns/modsecurity
/opt/docker/conf/crowdsec/patterns/mongodb
/opt/docker/conf/crowdsec/patterns/mysql
/opt/docker/conf/crowdsec/patterns/nagios
/opt/docker/conf/crowdsec/patterns/nginx
/opt/docker/conf/crowdsec/patterns/paths
/opt/docker/conf/crowdsec/patterns/postgresql
/opt/docker/conf/crowdsec/patterns/rails
/opt/docker/conf/crowdsec/patterns/redis
/opt/docker/conf/crowdsec/patterns/ruby
/opt/docker/conf/crowdsec/patterns/smb
/opt/docker/conf/crowdsec/patterns/ssh
/opt/docker/conf/crowdsec/patterns/tcpdump
/opt/docker/conf/crowdsec/postoverflows
/opt/docker/conf/crowdsec/postoverflows/s00-enrich
/opt/docker/conf/crowdsec/postoverflows/s00-enrich/rdns.yaml
/opt/docker/conf/crowdsec/postoverflows/s01-whitelist
/opt/docker/conf/crowdsec/postoverflows/s01-whitelist/cdn-whitelist.yaml
/opt/docker/conf/crowdsec/postoverflows/s01-whitelist/seo-bots-whitelist.yaml
/opt/docker/conf/crowdsec/profiles.yaml
/opt/docker/conf/crowdsec/scenarios
/opt/docker/conf/crowdsec/scenarios/apache_log4j2_cve-2021-44228.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2017-9841.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2019-18935.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-26134.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-35914.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-37042.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-40684.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-41082.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-41697.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-42889.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-44877.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2022-46169.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2023-22515.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2023-22518.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2023-49103.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2024-0012.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2024-38475.yaml
/opt/docker/conf/crowdsec/scenarios/CVE-2024-9474.yaml
/opt/docker/conf/crowdsec/scenarios/f5-big-ip-cve-2020-5902.yaml
/opt/docker/conf/crowdsec/scenarios/fortinet-cve-2018-13379.yaml
/opt/docker/conf/crowdsec/scenarios/gitea-bf.yaml
/opt/docker/conf/crowdsec/scenarios/gitea-scraper.yaml
/opt/docker/conf/crowdsec/scenarios/grafana-cve-2021-43798.yaml
/opt/docker/conf/crowdsec/scenarios/http-admin-interface-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-backdoors-attempts.yaml
/opt/docker/conf/crowdsec/scenarios/http-bad-user-agent.yaml
/opt/docker/conf/crowdsec/scenarios/http-crawl-non_statics.yaml
/opt/docker/conf/crowdsec/scenarios/http-cve-2021-41773.yaml
/opt/docker/conf/crowdsec/scenarios/http-cve-2021-42013.yaml
/opt/docker/conf/crowdsec/scenarios/http-cve-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-generic-bf.yaml
/opt/docker/conf/crowdsec/scenarios/http-generic-test.yaml
/opt/docker/conf/crowdsec/scenarios/http-open-proxy.yaml
/opt/docker/conf/crowdsec/scenarios/http-path-traversal-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-sap-interface-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-sensitive-files.yaml
/opt/docker/conf/crowdsec/scenarios/http-sqli-probing.yaml
/opt/docker/conf/crowdsec/scenarios/http-w00tw00t.yaml
/opt/docker/conf/crowdsec/scenarios/http-wordpress-scan.yaml
/opt/docker/conf/crowdsec/scenarios/http-xss-probing.yaml
/opt/docker/conf/crowdsec/scenarios/jira_cve-2021-26086.yaml
/opt/docker/conf/crowdsec/scenarios/netgear_rce.yaml
/opt/docker/conf/crowdsec/scenarios/pulse-secure-sslvpn-cve-2019-11510.yaml
/opt/docker/conf/crowdsec/scenarios/spring4shell_cve-2022-22965.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-bf.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-cve-2024-6387.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-generic-test.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-refused-conn.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-slow-bf.yaml
/opt/docker/conf/crowdsec/scenarios/ssh-time-based-bf.yaml
/opt/docker/conf/crowdsec/scenarios/thinkphp-cve-2018-20062.yaml
/opt/docker/conf/crowdsec/scenarios/vaultwarden-bf.yaml
/opt/docker/conf/crowdsec/scenarios/vmware-cve-2022-22954.yaml
/opt/docker/conf/crowdsec/scenarios/vmware-vcenter-vmsa-2021-0027.yaml
/opt/docker/conf/crowdsec/simulation.yaml
/opt/docker/conf/crowdsec/user.yaml
/opt/docker/conf/mailrise
/opt/docker/conf/mailrise/mailrise.conf
/opt/docker/conf/mattermost
/opt/docker/conf/mattermost/config.json
/opt/docker/conf/searxng
/opt/docker/conf/searxng/searxng-settings.yml
/opt/docker/conf/sillytavern
/opt/docker/conf/sillytavern/config.yaml
/opt/docker/conf/synapse
/opt/docker/conf/synapse/aipa_appservice.yaml
/opt/docker/conf/synapse/element-config.json
/opt/docker/conf/synapse/homeserver.yaml
/opt/docker/conf/traefik-ana
/opt/docker/conf/traefik-ana/acme.json
/opt/docker/conf/traefik-ana/config
/opt/docker/conf/traefik-ana/config/acme.json
/opt/docker/conf/traefik-ana/config/dynamic.yml
/opt/docker/conf/traefik-ana/config/traefik.yml
/opt/docker/conf/vaultwarden
/opt/docker/conf/vaultwarden/config.json

===== LISTENING PORTS =====

0.0.0.0:111
0.0.0.0:22
0.0.0.0:222
0.0.0.0:3000
0.0.0.0:3100
0.0.0.0:41412
0.0.0.0:443
0.0.0.0:5001
0.0.0.0:80
0.0.0.0:8000
0.0.0.0:8025
0.0.0.0:8088
0.0.0.0:8090
0.0.0.0:8100
0.0.0.0:8380
0.0.0.0:8780
0.0.0.0:9080
0.0.0.0:9180
0.0.0.0:9898
0.0.0.0:9996
[::]:111
127.0.0.1:42675
*:21115
*:21116
*:21117
*:21118
*:21119
[::]:22
[::]:222
*:2375
[::]:3000
[::]:3100
[::]:41412
[::]:443
[::]:5001
[::]:80
[::]:8000
[::]:8025
[::]:8088
[::]:8090
[::]:8100
[::]:8380
[::]:8780
[::]:9080
[::]:9180
[::]:9898
[::]:9996

===== MODEL / HUGGINGFACE CACHES =====


===== DOCKER-ADJACENT SYSTEMD SERVICES =====

containerd.service running
docker.service running

===== DONE =====

Paste the above back into the chat, or pass a path as argv[1] to save.
